Advisory
On 10.02.2026 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within BI/BO platform.
SAP Note 3678282 addresses "[CVE-2026-0485] Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform" to prevent denial of service (dos) with a high risk for exploitation.
A workaround does exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Denial of Service (DoS) attacks that take a system offline may lead to significant cost for the company, studies quantify the costs in average between 4 and 5 millions dollars. Business continuity requires SAP systems staying online. The CVSS scores or vulnerability descriptions are not enough to represent how a simple bug can lead to a significant loss for companies.
Risk specification
SAP BusinessObjects BI Platform allows an unauthenticated attacker to send oversized requests that repeatedly crash and restart the Content Management Server, potentially resulting in a persistent service outage.
Solution
SAP BusinessObjects BI Platform now validates the size of all data exchanged between processes, ensuring that oversized or malformed requests are safely rejected and that the Content Management Server remains stable and fully operational. Circumstances exist that prevent the timely installation of a patch provided by the manufacturer. In such cases, you may consider applying the suggested workaround as a temporary or compensating mitigation: "Implement CORBA SSL configuration as described in the Configuring backend servers for SSL section of the "Securing the BI platform" chapter in the Business Intelligence Platform Administrator Guide.".
Affected System
SAP BusinessObjects Business Intelligence suite is an analytics platform allowing SAP customers to make better decisions based on their business data. SAP BI is a module meant for producing business insights and expands its power in combination with HANA DB and also exists as BW/4 HANA. Due to processing sensitive business data, the Data security is of utmost importance.
The advisory is valid for
- ENTERPRISE 2025 27
- ENTERPRISE 2027 16
- ENTERPRISE 430 101
